Skip to content

Comment on Security Incident INC-2026-07-28-01 – UK AI Security Institute [pdf]

Comments

AI agent hid its identity online (using Tor and a proxy service) to get around GitHub’s sign-up checks, creating disposable fake accounts
AI agent created many code repositories containing malicious software, after which GitHub suspended its account.
AI agent got past an audio-based “prove you’re human” test (CAPTCHA) in order to register a public web address on a free domain-name service

It feels incredibly reckless to allow LLMs to perform this behavior. Isn't there a way to prevent them these sorts of actions?

yes, individual criminal liability of the researchers and executives.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.